CVE detail
CVE-2020-5415 — CVE-2020-5415
Published 2020-08-12 · Modified 2026-06-17 · Vendor pivotal_software · Product concourse · Source nvd
CRITICAL
severity
CVSS-derived band
0.0122
EPSS probability
exploitation probability, 30d
66.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Concourse, versions prior to 6.3.1 and 6.4.1, in installations which use the GitLab auth connector, is vulnerable to identity spoofing by way of configuring a GitLab account with the same full name as another user who is granted access to a Concourse team. GitLab groups do not have this vulnerability, so GitLab users may be moved into groups which are then configured in the Concourse team.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References